2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-6278 | — | — | 3.2% | Sep 28, 2015 | The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and... |
| CVE-2015-6012 | — | — | 1.2% | Sep 28, 2015 | Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 20... |
| CVE-2015-6011 | — | — | 1.2% | Sep 28, 2015 | Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduc... |
| CVE-2015-6010 | — | — | 1.2% | Sep 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-e... |
| CVE-2015-6009 | — | — | 1.5% | Sep 28, 2015 | Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to e... |
| CVE-2015-6008 | — | — | 4.8% | Sep 28, 2015 | install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands ... |
| CVE-2015-6007 | — | — | 0.7% | Sep 28, 2015 | Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote atta... |
| CVE-2015-3974 | — | — | 1.9% | Sep 28, 2015 | EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Auto... |
| CVE-2015-6475 | — | — | 1.1% | Sep 26, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote atta... |
| CVE-2015-6474 | — | — | 1.4% | Sep 26, 2015 | IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML s... |
| CVE-2015-6470 | — | — | 1.1% | Sep 26, 2015 | Resource Data Management Data Manager before 2.2 allows remote authenticated users to modify arbitrary passwords via uns... |
| CVE-2015-6469 | — | — | 1.4% | Sep 26, 2015 | The interpreter in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allows remote attackers to discover script source cod... |
| CVE-2015-6468 | — | — | 0.6% | Sep 26, 2015 | Cross-site request forgery (CSRF) vulnerability in Resource Data Management Data Manager before 2.2 allows remote attack... |
| CVE-2015-6454 | — | — | 2.5% | Sep 26, 2015 | Everest PeakHMI before 8.7.0.2, when the video server is used, allows remote attackers to cause a denial of service (inc... |
| CVE-2015-6306 | — | — | 1.0% | Sep 26, 2015 | Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, ... |
| CVE-2015-6305 | — | — | 1.2% | Sep 26, 2015 | Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne... |
| CVE-2015-6302 | — | — | 2.1% | Sep 26, 2015 | The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and 7.0(252.0) allows r... |
| CVE-2015-6282 | — | — | 2.2% | Sep 26, 2015 | Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15... |
| CVE-2015-4543 | — | — | 2.3% | Sep 26, 2015 | EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remot... |
| CVE-2015-4542 | — | — | 2.8% | Sep 26, 2015 | EMC RSA Archer GRC 5.x before 5.5.3 allows remote authenticated users to bypass intended access restrictions, and read o... |
| CVE-2015-4541 | — | — | 1.8% | Sep 26, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.5.3 allow remote authenticated us... |
| CVE-2015-4540 | — | — | 1.2% | Sep 26, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 6.8.1 P18 a... |
| CVE-2015-4539 | — | — | 1.6% | Sep 26, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 7.0.0 allow... |
| CVE-2015-7375 | — | — | 2.2% | Sep 25, 2015 | Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of... |
| CVE-2015-7374 | — | — | 2.9% | Sep 25, 2015 | The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbit... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now